Skip to main content
October 11, 2021
Question

1Password8/Windows and Windows Hello on first signin?

  • October 11, 2021
  • 47 replies
  • 1211 views

Hi! I'm trying to figure out why manually entering my master password is required on first run of the 1Password 8 app on Windows, and Windows Hello can only be used after initial sign in when 1Password relocks. On iPhone/iPad (and maybe Mac?), you can use FaceID for the initial sign in. Is that difference intentional (it seems like it from the release notes), and if so what is the reasoning?

Thanks!


1Password Version: 8.2.2
Extension Version: Not Provided
OS Version: Windows 11

47 replies

Naxterra
October 12, 2021

For some reason AgileBits team doesn't trust TPM chip and Windows, but they trust Apple products.

1P_PeterG
1Password Alum
October 13, 2021

Hi @millercentral, thanks for this question!

The difference is indeed intentional, and your comparison between Apple and Windows products is an informative one. Here's a little more about that, our current thinking, and what might come next.

On Apple products, there is a physical system built into the device called the Secure Enclave - you can read more about it at the link, but to borrow from Apple's official documentation:

The Secure Enclave is a dedicated secure subsystem [...] The Secure Enclave is isolated from the main processor to provide an extra layer of security and is designed to keep sensitive user data secure even when the Application Processor kernel becomes compromised.

In other words, Apple has provided a standard method for storing sensitive data between reboots. This includes your FaceID / TouchID data. 👍

On the Windows side, there is a rough equivalent to this, called the TPM. While relatively common in business settings, it still isn't used across large swaths of the PC ecosystem. What this means in practice is that 1Password doesn't uniformly have a secure place to store a cryptographic secret on-disk (besides, uh, in our own app, which doesn't help when that's the thing you're trying to unlock. 🤔).

So you end up with a situation where the choice is either:

  1. Leave a cryptographic secret (which is used to unlock Hello) on a disk that is likely not encrypted (bad)
  2. Require the account password the first time a user logs in

However, TPM adoption is likely to increase with Windows 11, and we're very interested in how we might bring Secure Enclave-like functionality to the Windows platform. I don't have anything specific to share on that at the moment, but it's definitely on our radar!

I hope that makes sense. Let me know if this answers your question, and thanks for taking the time to bring it up 😀

October 13, 2021

It does, thank you for the response. I'm running Win11 (with TPM active), so if there is a Win11-specific opportunity here I'm all for it and sign me up to test. :)

October 14, 2021

Thank you for this @millercentral :+1: And on behalf of Peter, you are very welcome :)

October 14, 2021

@1P_PeterG Is it not possible to check if TPM is active and store the secret there? That way, those of us who have TPM can use Hello even after initial sign in?

1P_PeterG
1Password Alum
October 20, 2021

@pratnala it may be possible, but my understanding is that TPM usage wasn't something we were seeing much of overall on the Windows side. We expect that to change soon, though, and again are very interested in matching the ease of use already made possible by Secure Enclave on Apple hardware. 😀

1P_PeterG
1Password Alum
February 23, 2022

Hi @millercentral @pratnala , we have an update for you!

In the latest Beta (8.6.0-43) we have brought TPM support to our Windows Hello integration, enabling you to unlock with Windows Hello after restarting 1Password or rebooting your machine. 🥳

If you're interested to give it a try, we'd love to have your impressions of the new feature!

https://1password.community/discussion/127435/beta-6-of-the-year-is-now-available#latest

Thanks again for providing the initial feedback, as well. It's requests like these that continue to drive our improvements going forward.

February 24, 2022

Wow, this is great!

February 24, 2022

Hi @1P_PeterG , that's great news, I've tried to turn it on right away in the new beta, however the option to use TPM is grayed out for me and it seems I cannot change this setting, even after restarting 1PW multiple times.

My PC have TPM 2.0, so I guess that shouldn't be the issue. What should I check to get the bottom of this grayed out option?

February 24, 2022

@1P_PeterG Just tried out the beta and it works great for me!